Skip to content

Audit & Assurance

ERP Pre and Post Implementation Review

The controls in an ERP are configured once, usually under deadline pressure, and then inherited for a decade. Independent review before go-live is materially cheaper than remediation afterwards.

Pre-implementation: go-live readiness

Conducted before cut-over, while findings can still change the outcome. Because the system is not yet live, conclusions are on design rather than operating effectiveness — we state that explicitly in the report rather than implying assurance we cannot give.

  • Programme governance, steering effectiveness and decision authority.
  • Requirements traceability — whether what is being built is what was approved.
  • Configuration of application controls: approval workflows, tolerance limits, three-way match, validation rules.
  • Segregation of duties in the role and authorisation design, tested for conflicting combinations before they are granted.
  • Data migration controls — completeness, accuracy, reconciliation and the sign-off trail.
  • Interface design and reconciliation controls between the ERP and surrounding systems.
  • Testing adequacy — whether UAT actually covered the control requirements, with evidence.
  • Cut-over plan, fallback plan, and the criteria on which go-live will be authorised.
  • Readiness of security administration, change management and support processes for day one.

Post-implementation review

Usually three to six months after go-live, once a full period cycle has run. Here we can test operating effectiveness: whether the configured controls are working, whether workarounds have emerged, whether emergency access granted during cut-over was ever revoked, and whether the segregation of duties design survived contact with reality.

Two engagements, two different conclusions

Cut-over Pre-implementation Design and readiness only. Acontrol cannot be tested beforeit has operated. Post-implementation Operating effectiveness, 3–6months on, once a full periodcycle has run.

Platforms

SAP including S/4HANA, Oracle E-Business Suite and Fusion, Microsoft Dynamics 365, and core banking and insurance platforms. We audit the control configuration; we do not implement, and we hold no implementation partner status with any vendor — so the finding is not shaped by a channel relationship.

How the engagement runs

  1. 1

    Programme understanding

    Review scope, timeline, governance and the control requirements the programme committed to deliver.

  2. 2

    Control design review

    Assess configured application controls and the role and authorisation design against the risks they must address.

  3. 3

    Segregation of duties analysis

    Systematically test the role design for conflicting access combinations before roles are provisioned.

  4. 4

    Data migration assurance

    Review reconciliation controls, sample-test migrated data and assess the sign-off trail.

  5. 5

    Readiness assessment

    Evaluate testing evidence, cut-over readiness and the state of supporting processes.

  6. 6

    Reporting

    Report against the go-live decision date, so findings arrive while they can still change something.

What you receive

Go-live readiness assessment with a clear, defensible recommendation
Application control design review by module
Segregation of duties conflict matrix and remediation options
Data migration assurance report with reconciliation results
Findings register rated by significance and go-live impact
Post-implementation review at an agreed interval after cut-over

Frequently asked questions

Early enough that findings can be acted on — typically at the point configuration is largely complete and UAT is underway. Bringing in an independent reviewer two weeks before cut-over produces a report nobody can act on without delaying go-live, which helps no one.

No, and any firm that says otherwise is misrepresenting what is possible. A control cannot be tested for operating effectiveness before it has operated. Pre-implementation conclusions are on design and readiness. Operating effectiveness comes from the post-implementation review.

Because the implementation partner is assessing its own delivery, usually against a fixed-price milestone. That is not independent assurance and your audit committee should not treat it as such.

Related services

Related regulatory frameworks

Need an independent view?

Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.

Request a proposal
Top